Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.0
CVE-2008-4616EPSS 7%
The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-supplied values to calculate a …
Spambam Plugin
Mitigation only
MEDIUM 5.1
CVE-2008-4106EPSS 5%
WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_l…
WordPress
after 2.6.1
HIGH 7.5
CVE-2008-3747
The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL commun…
WordPress
Patch available
HIGH 10.0
CVE-2008-3362EPSS 17%
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to exe…
Wp Downloads Manager
No fix yet
HIGH 7.5
CVE-2008-2510
SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands vi…
Upload File Plugin
Mitigation only
HIGH 9.0
CVE-2008-2392
Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary…
WordPress
after 2.5.1
HIGH 7.5
CVE-2008-2146
wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attacke…
WordPress
after 2.2.2
HIGH 7.5
CVE-2008-2034
SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute…
Download Monitor Plugin
Mitigation only
HIGH 7.5
CVE-2008-1930EPSS 5%
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote …
WordPress
Patch available
HIGH 7.5
CVE-2008-1982
SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote attackers to execute arbitrar…
Wpss
after 0.6
HIGH 7.5
CVE-2008-1646
SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands …
Wp Download
No fix yet
HIGH 7.5
CVE-2008-1059EPSS 48%
PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers …
Sniplets Plugin
No fix yet
HIGH 7.5
CVE-2008-1060EPSS 44%
Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary…
Sniplets Plugin
No fix yet
HIGH 7.5
CVE-2008-0939
Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arb…
Photo Album Plugin
No fix yet
HIGH 7.5
CVE-2008-0845
SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 1.6.1 for WordPress allows remote attackers to execute arbitrary SQ…
Dean Logan Wp People Plugin
Mitigation only
HIGH 7.5
CVE-2008-0682
SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL com…
Wordspew
after 3.71
HIGH 7.5
CVE-2008-0683
SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to exec…
St Newsletter Plugin
No fix yet
MEDIUM 6.4
CVE-2008-0664
The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog …
WordPress
Patch available
HIGH 7.5
CVE-2008-0507
SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the …
Adserve
No fix yet
HIGH 7.5
CVE-2008-0520
Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary S…
Wassup Plugin
after 1.4.3
MEDIUM 6.8
CVE-2008-0508
Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows …
Permalinks Migration Plugin
Patch available
HIGH 7.5
CVE-2008-0490
SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL comman…
Wp Cal Plugin
No fix yet
MEDIUM 6.8
CVE-2008-0388
SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user paramet…
Wp Forum
No fix yet
HIGH 7.5
CVE-2008-0222EPSS 8%
Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and ex…
Filemanager
No fix yet
HIGH 7.5
CVE-2008-0194
Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrar…
WordPress
after 2.0.3
MEDIUM 5.0
CVE-2008-0191
WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, wh…
WordPress
Mitigation only
MEDIUM 5.0
CVE-2008-0195
WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts …
WordPress
after 2.0.11
MEDIUM 5.0
CVE-2008-0196
Multiple directory traversal vulnerabilities in WordPress 2.0.11 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1)…
WordPress
after 2.0.11
MEDIUM 5.0
CVE-2007-6369EPSS 8%
Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow remote attackers to read arbi…
Pictpress
after 0.91
MEDIUM 6.8
CVE-2007-6318EPSS 9%
SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the…
WordPress
No fix yet